#20031 closed enhancement (fixed)
httpd-2.4.61
Reported by: | Bruce Dubbs | Owned by: | Tim Tassonis |
---|---|---|---|
Priority: | elevated | Milestone: | 12.2 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (8)
comment:3 by , 9 months ago
Careful when updating apache, they more or less silenty threw out AddType and replaced it with AddHandler, resultung in php configs not working anymore....
comment:4 by , 9 months ago
Summary: | httpd-2.4.60 → httpd-2.4.61 |
---|
comment:6 by , 9 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed in commit 60314d0869, issued sa-12.1-067
comment:7 by , 9 months ago
Priority: | normal → elevated |
---|
The PHP bug was also assigned a CVE, so the SA needs to be updated for that:
Severity: important Affected versions: - Apache HTTP Server 2.4.60 Description: A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.61, which fixes this issue. References: https://httpd.apache.org/security/vulnerabilities_24.html https://httpd.apache.org/ https://www.cve.org/CVERecord?id=CVE-2024-39884 Timeline: 2024-07-01: reported
What I'll do for that is just note the additional CVE number and update the text a bit.
comment:8 by , 9 months ago
Well, I don't think that's neccessary, as the php bug was fixed in 2.0.61, and we never had 2.0.60 in the first place.
Note:
See TracTickets
for help on using tickets.